#GoPhish
Anglerphish — A Feature-Rich Gophish Fork
Anglerphish — A Feature-Rich Gophish Fork
From Side Project to an Upgraded Gophish Platform
infosecwriteups.com
March 31, 2026 at 7:01 AM
Vous cherchez une solution pour tester votre organisation avec des campagnes de « phishing ».

Voici un outil Open Source très cool ! 😜

getgophish.com
Gophish - Open Source Phishing Framework
Gophish - An Open-Source Phishing Framework
getgophish.com
November 24, 2024 at 8:35 PM
Today's your last chance to get 10% off your order when you use the code "GoPhish" at checkout!

bluescreenapparel.com
December 15, 2024 at 4:59 PM
the amount of businesses that use GoPhish as an otherwise legitimate mailer is ... concerning
December 8, 2025 at 3:51 PM
gophish (⭐️ 14305)

Open-Source Phishing Toolkit

#go
October 8, 2026 at 6:47 AM
gophish (⭐️ 14302)

Open-Source Phishing Toolkit

#go
October 7, 2026 at 4:45 PM
Blue Screen Apparel was the target of a Phishing scam.

Luckily we were able to verify that our store is in good standing with Shopify and there's nothing to worry about <3

For your support, use code "GoPhish" at checkout to get 10% off your order at bluescreenapparel.com
December 13, 2024 at 4:39 AM
goPhish
April 26, 2025 at 10:00 AM
Pretty sure I'm on the naughty list because I hacked Santa... #indiegame #indiedev #wishlist #christmas #GOPHISH
December 23, 2025 at 3:00 AM
🚨 EUVD-2026-94398
📊 6.3/10
🏢 Gophish

📝 Gophish through 0.12.1 contains a timing discrepancy vulnerability in AdminServer.Login that allows unauthenticated attackers to enumerate valid usernames...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-94398

#cybersecurity #infosec #cve #euvd
October 7, 2026 at 5:01 PM
🚨 EUVD-2026-94401
📊 7.1/10
🏢 Gophish

📝 Gophish through 0.12.1 contains an insecure direct object reference vulnerability that allows authenticated users to take over other users' groups, templa...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-94401

#cybersecurity #infosec #cve #euvd
October 7, 2026 at 5:01 PM
🚨 EUVD-2026-94402
📊 6.9/10
🏢 Gophish

📝 Gophish through 0.12.1 contains a rate limit bypass vulnerability that allows unauthenticated attackers to evade /login throttling by spoofing X-Forwarded...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-94402

#cybersecurity #infosec #cve #euvd
October 7, 2026 at 5:01 PM
🚨 EUVD-2026-94403
📊 2.3/10
🏢 Gophish

📝 Gophish through 0.12.1 contains stored and reflected cross-site scripting vulnerabilities that allow attackers to inject script by returning malicious SMT...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-94403

#cybersecurity #infosec #cve #euvd
October 7, 2026 at 5:01 PM
🚨 EUVD-2026-94404
📊 5.3/10
🏢 Gophish

📝 Gophish 0.11.0 through 0.12.1 contains a server-side request forgery vulnerability that allows authenticated low-privileged users to reach loopback and pr...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-94404

#cybersecurity #infosec #cve #euvd
October 7, 2026 at 5:01 PM
gophish is a good name for a configuration library for Go 😆
December 18, 2024 at 10:00 AM
Gophish Framework Used in Phishing Campaigns to Deploy Remote Access Trojans #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
October 22, 2024 at 6:22 PM
I wanted to try out sculpting in Blender. Turned out pretty well! I might keep messing with more sculpting in the future. They are pretty fun to make and mess with. :3
OC: GoPhish the hyena
#blender3d #blendersculpting #furryart #furry3d #furryartist
June 23, 2026 at 9:40 PM
I just finished preparing a ton of updated phishing templates and educational landing pages for training. It's intended for use with our AWS/Azure versions of GoPhish, but it's open-source so feel free to use it for your own trainings! github.com/HailBytes/go...

#infosec #cybersecurity #education
GitHub - HailBytes/gophish-training-templates: Professional email templates and landing pages for employee security awareness phishing simulations using GoPhish. Ready-to-deploy campaigns with realist...
Professional email templates and landing pages for employee security awareness phishing simulations using GoPhish. Ready-to-deploy campaigns with realistic scenarios, educational content, and custo...
github.com
June 13, 2025 at 5:04 AM
I have some news - my daughter’s Sr project is live and available for free as an extension on Google Chrome.

chromewebstore.google.com/detail/gophi...
GoPhish! - Chrome Web Store
Enjoy safer browsing with GoPhish! Open links from your email or the web with GoPhish to learn more about them.
chromewebstore.google.com
April 3, 2026 at 2:25 AM
Blue Screen Apparel was the target of a Phishing scam.

Luckily we were able to verify that our store is in good standing with Shopify and there's nothing to worry about <3

For your support, use code "GoPhish" at checkout to get 10% off your order at bluescreenapparel.com
December 13, 2024 at 4:40 AM
Short blogpost on searching for "gophish"-simulation pages. Really like posts like these, just an easy to understand walkthrough

intelinsights.substack.com/p/uncovering...
Uncovering GoPhish Deployments
Patterns, Tools, and Techniques
intelinsights.substack.com
December 30, 2024 at 8:07 AM
🔥 𝗘𝗻𝘃𝗶𝗲 𝗱𝗲 𝘁𝗲𝘀𝘁𝗲𝗿 𝘃𝗼𝘀 𝘂𝘁𝗶𝗹𝗶𝘀𝗮𝘁𝗲𝘂𝗿𝘀 𝗮𝘃𝗲𝗰 𝘂𝗻𝗲 𝗰𝗮𝗺𝗽𝗮𝗴𝗻𝗲 𝗱𝗲 𝗽𝗵𝗶𝘀𝗵𝗶𝗻𝗴 ?

Nous vous proposons un tutoriel qui explique comment installer et configurer 𝗚𝗼𝗽𝗵𝗶𝘀𝗵 pour créer une 𝗰𝗮𝗺𝗽𝗮𝗴𝗻𝗲 𝗱𝗲 𝗽𝗵𝗶𝘀𝗵𝗶𝗻𝗴 avec un 𝘁𝗲𝗻𝗮𝗻𝘁 𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 𝟯𝟲𝟱 !

📄 www.it-connect.fr/sensibilisat...

#gophish #phishing #sensibilisation #it
May 8, 2025 at 1:45 PM
Simulating Phishing Attacks with Gophish: A Comprehensive Guide
Simulating Phishing Attacks with Gophish: A Comprehensive Guide
Credit Phishing is one of the most common tactics cybercriminals use to steal sensitive data like login credentials, financial details, and personal information. While anti-phishing technologies are continuously improving, phishing attacks remain a significant threat due to the ongoing cat-and-mouse game between attackers and defenders. Unfortunately, human error is still a major vulnerability, with employees often being the weakest link in an organization’s security. Source: Cloudflare What is Gophish and How Does It Work? Gophish is an open-source phishing framework that helps organizations test their readiness against phishing attacks. With Gophish, you can create custom phishing email templates, launch targeted campaigns, and track responses in real-time. It’s a user-friendly tool developed in Go that works on Windows, Mac, and Linux operating systems, and also provides a Docker container for easy deployment. What is Railway? Railway Railway is a modern cloud platform that simplifies the process of deploying production-ready applications. In this guide, we will use Railway to deploy Gophish quickly and with minimal configuration. Step-by-Step Guide to Deploying Gophish Using Railway To deploy Gophish with Railway, you first need to fork the Gophish repository and set up a new Railway project. Here’s how you can get started: Fork the Gophish Repository : Log in to your GitHub account and fork the Gophish repository . Fork the repo Create a New Railway Project : Sign up for Railway and link your GitHub account. Deploy the Gophish project directly from your forked repository. Create a New Project Deploy from GitHub repo The deployment will begin right away, but there are a few additional steps required to properly configure Gophish Configure Deployment Settings : Once the deployment is finished, go to Settings &gt; Domains and click Generate Domain to expose the service publicly. Generating the Domain Railway will assign a default xxx.up.railway.app domain. Create a New Variable : In the Variables tab, add a new variable called PORT with the value 3333 (the port the admin server listens on). Check the Logs for Credentials : Head to Deployments and click View Logs . Look for a log entry that contains the message: “Please log in with the username admin and the password XXXXXXXXX.” Checking logs for credentials Update config.json : Modify the config.json file in your forked Gophish repository: Change listen_url from 127.0.0.1:3333 to 0.0.0.0:3333 to allow the service to listen on the public IP. Set use_tls to false since Railway handles the TLS connection. Add your Railway domain to trusted_origins, for example, "xxx.up.railway.app", or use your custom domain. config.json Commit Changes and Deploy : After committing your changes, Railway will automatically trigger the deployment again. If everything is set up correctly, you’ll see the Gophish Admin Login Page when you access the deployment URL. Gophish Admin Login Page Running Phishing Attack Simulations: A Hands-On Approach Gophish Dashboard Once your Gophish instance is deployed, log into the admin panel and update the password for security purposes. You can now configure your phishing attack simulations to mimic real-world threats by setting up the following elements: Users and Groups : Create specific users or groups to target with phishing emails. Creating the User Groups Email Templates : Customize phishing email templates with realistic content, attachments, and links. Creating the Phishing Template Sending Profiles : Set up SMTP relay details to send the phishing emails. Landing Pages : Build fake landing pages where users are redirected after clicking phishing links. After configuring these elements, you can start a phishing campaign. Navigate to the Campaigns section, create a new campaign, and select the appropriate email templates and landing pages. Once the campaign is launched, monitor its progress in real-time through the dashboard. Create new Gophish campaign Tracking Campaign Effectiveness While it’s crucial that employees recognize phishing attempts and avoid falling victim, tracking the results of your simulations is just as important. Gophish provides instant feedback, showing which users clicked on links, entered sensitive information, and more. While it may not have all the advanced features of premium phishing simulation tools, Gophish is a great option for organizations on a budget or those just starting to explore phishing simulations. Source: getgophish.com Phishing simulations are a valuable tool for assessing and improving your organization’s security posture. They help raise awareness among employees and allow you to identify weak spots in your training program. With Gophish, you can easily launch phishing campaigns and track results, making it an excellent solution for both small startups and large enterprises looking to enhance their cybersecurity awareness. Stay vigilant, stay informed, and stay secure! Thank You for Reading! Your interest and attention are greatly appreciated. https://medium.com/media/09e68e2afeae42baf7318c0062e945f2/href Simulating Phishing Attacks with Gophish: A Comprehensive Guide was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.
infosecwriteups.com
February 18, 2025 at 5:09 AM
GoPhish & EvilGinx2 😊
October 11, 2025 at 4:11 AM
🔥 La 𝘀𝗲𝗻𝘀𝗶𝗯𝗶𝗹𝗶𝘀𝗮𝘁𝗶𝗼𝗻 𝗱𝗲𝘀 𝘂𝘁𝗶𝗹𝗶𝘀𝗮𝘁𝗲𝘂𝗿𝘀 est essentielle et l'utilisation de l'outil 𝗼𝗽𝗲𝗻 𝘀𝗼𝘂𝗿𝗰𝗲 𝗚𝗼𝗽𝗵𝗶𝘀𝗵 est l'occasion de les tester de façon régulière !

📄 Voici le lien vers le tuto, n'hésitez pas à partager :
www.it-connect.fr/sensibilisat...

#phishing #microsoft365 #phishing #sensibilisation
February 4, 2025 at 4:00 PM